Critical Vulnerability in Junos OS
A critical vulnerability in J-Web of Junos OS SRX Series and EX Series could allow pre-authentication remote code execution
Summary
A critical vulnerability in J-Web of Junos OS SRX Series and EX Series could allow pre-authentication remote code execution
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
An out-of-bounds write vulnerability in J-Web of Juniper Networks Junos OS SRX Series and EX Series allows an unauthenticated, network-based attacker to cause a denial-of-service (DoS), or remote code execution (RCE) and obtain root privileges on an affected device. The vulnerability, assigned CVE-2024-21591, has a CVSSv3 score of 9.8 and is caused by use of an insecure function allowing an attacker to overwrite arbitrary memory.
Proof-of-concept available for CVE-2024-21591
A proof-of-concept for the exploitation of CVE-2024-21591 has been publicly released. Exploitation of this vulnerability is more likely.
Threat updates
| Date | Update |
|---|---|
| 13 Feb 2024 |
Proof-of-concept available for CVE-2024-21591
Proof-of-concept publicly available for exploitation of CVE-2024-21591 The cyber alert has been updated to reflect this change. |
Remediation advice
Affected organisations are encouraged to review the Juniper Junos OS Security Bulletin and apply any relevant updates.
Definitive source of threat updates
Last edited: 13 February 2024 3:15 pm